Skip to content

fix(OMN-15737): admit Dep Provenance Gate into CI Summary EXPECTED_EXTERNAL_CONTEXTS - #2684

Merged
jonahgabriel merged 10 commits into
devfrom
jonah/omn-15737-wire-dep-provenance-gate-external-context
Aug 21, 2026
Merged

jonahgabriel merged 10 commits into
devfrom
jonah/omn-15737-wire-dep-provenance-gate-external-context

Conversation

@jonahgabriel

@jonahgabriel jonahgabriel commented Aug 8, 2026 •

Copy link
Copy Markdown
Collaborator

OMN-15737

OMN-13873 (Done) shipped Dep Provenance Gate (dep-provenance-gate.yml, job dep-provenance-gate) but its own DoD item "Gate workflow present and required on infra dev/main branch protection" was never fulfilled live. Live readback today:

  • omnibase_infra dev required_status_checks: ["CI Summary"] only — Dep Provenance Gate absent
  • omnibase_infra main required_status_checks: 5-context set, also absent
  • scripts/ci/ci_summary_gate.py's EXPECTED_EXTERNAL_CONTEXTS (the OMN-15496 mechanism that fail-closed-asserts cross-workflow contexts through the sole required CI Summary umbrella) did not include it

So the gate runs on every PR (no job-level if: — it always executes and reports) but currently blocks nothing on dev or main.

Measurement (per the file's own admission rule)

16/16 merged omnibase_infra dev PRs (#2646–#2669, 2026-08-04T16:56Z → 2026-08-07T01:08Z), started_at <= mergedAt:

PR conclusion
2646–2669 (all 16) success

16/16 present, 16/16 green.

Cross-checked against the SAME #2546–#2567 golden-fixture window test_no_wedge_replay_over_sixteen_merged_dev_prs already pins:

16/16 present, 16/16 green (also folded into tests/ci/fixtures/omn15496_merge_time_external_check_runs.json).

Both independent 16-PR windows agree — qualifies cleanly under the admission rule.

Fix

Add "Dep Provenance Gate" to EXPECTED_EXTERNAL_CONTEXTS in scripts/ci/ci_summary_gate.py. Closes the gap fail-closed on dev via the existing CI Summary umbrella — the code path per CLAUDE.md rule 10, no branch-protection API mutation in this PR. Adding it to main's direct required_status_checks is a separate branch-protection mutation left for the operator.

Incidental fix bundled (pre-existing, unrelated to the above)

scripts/sync-node-migrations.sh --check (always_run: true pre-commit hook) was already red on origin/dev HEAD before this change — 2 omnimarket node migrations (node_canary_score_reducer/0003_capability_scores_tenant_id_to_uuid.sql, node_projection_registration/0004_node_service_registry_no_force_rls.sql) existed upstream but were never vendored into docker/migrations/forward/nodes/. Since this hook blocks any commit to the repo regardless of diff content, it had to be fixed to land this PR at all (no-pre-existing-excuse policy). Vendored both files and declared them in docker/migrations/forward/_ledger/application-migrations.tsv following the established pattern for each node (not new policy):

  • node_canary_score_reducer/0003: domain=tenant, continuing sibling 0002's tenant domain for the same already-tenant-classified column.
  • node_projection_registration/0004: domain=omninode_internal, matching the file's own inline OMN-15336 item-4 domain corroboration.

test_application_migration_manifest.py's pinned declaration count updated 94 → 96 accordingly.

Verification

  • tests/ci/test_ci_summary_gate.py: 52 passed
  • tests/unit/scripts/validation/test_application_migration_manifest.py: 8 passed
  • Full impacted suite (governed selector: scripts/ci/tests/ scripts/tests/ tests/ci/ tests/scripts/ tests/unit/scripts/, --ignore=tests/integration): 3011 passed, 5 skipped

Zero AWS/prod mutation. Zero branch-protection API mutation.

Evidence-Ticket: OMN-15737
Evidence-Source: OCC#6198

@coderabbitai

coderabbitai Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your current included review allowance is based on your included PR review attempts over the past 7 days.

Next review available in: 10 minutes

Limit details: You’ve used the included review currently available. Your 116 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 89a91c86-31ff-4564-b073-226341ca87f9

📥 Commits

Reviewing files that changed from the base of the PR and between 6494944 and 288e143.

📒 Files selected for processing (3)
  • scripts/ci/ci_summary_gate.py
  • tests/ci/fixtures/omn15496_merge_time_external_check_runs.json
  • tests/ci/fixtures/omn15979_merge_time_external_check_runs.json

Comment @coderabbitai help to get the list of available commands.

@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

OCC autobind did not mint a companion for this PR: no changed-file candidate could be proven RED against the merge base, and emitting a PR-existence probe instead would be non-falsifiable evidence (OMN-15247). Hand-authored evidence is required.

jonahgabriel pushed a commit to OmniNode-ai/onex_change_control that referenced this pull request Aug 8, 2026
#6198)

* evidence: OCC companion pass 1 for OmniNode-ai/omnibase_infra#2684

* evidence: OCC companion self-bind for #6198

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
…TERNAL_CONTEXTS

OMN-13873 shipped `Dep Provenance Gate` (dep-provenance-gate.yml) but its own
DoD item "required on infra dev/main branch protection" was never fulfilled
live: the context reports on every PR (no job-level `if:`) but blocks
nothing on dev or main today.

Measured per ci_summary_gate.py's own admission rule: 16/16 present, 16/16
green over the last 16 merged omnibase_infra dev PRs (#2646-#2669,
2026-08-04T16:56Z -> 2026-08-07T01:08Z, started_at <= mergedAt). Re-verified
against the SAME #2546-#2567 golden-fixture window already pinned by
test_ci_summary_gate.py: also 16/16 present, 16/16 green. Both windows agree,
so the context is folded into EXPECTED_EXTERNAL_CONTEXTS and the existing
fixture rows, closing it fail-closed on dev via the sole required `CI
Summary` umbrella (code path per CLAUDE.md rule 10 — no branch-protection
API mutation in this PR).

Also bundles a pre-existing, unrelated node-migration vendor-sync drift fix
(scripts/sync-node-migrations.sh output) that was already red on dev HEAD
before this change and blocked the pre-commit gate for this PR
(no-pre-existing-excuse policy).
The previous commit's json.dump reformatted the whole fixture file (2-space
indent vs the file's original 1-space convention), producing an 8000-line
diff noise. Re-dump with indent=1 to match the existing style; diff is now
scoped to the actual added rows.
…anifest

test_application_migration_manifest.py caught what the bundled vendor-sync
fix (previous commit) missed: adding node_canary_score_reducer/0003 and
node_projection_registration/0004 to the vendor tree without a matching
declaration in docker/migrations/forward/_ledger/application-migrations.tsv
left the manifest incomplete (94 declared vs 96 on disk).

Domain classification follows the established, already-committed pattern
for each node rather than inventing new policy:
- node_canary_score_reducer/0003 (capability_scores tenant_id TEXT->UUID):
  domain=tenant, continuing sibling 0002's tenant domain for the same
  already-tenant-classified column.
- node_projection_registration/0004 (node_service_registry NO FORCE RLS):
  domain=omninode_internal, matching the file's own inline OMN-15336
  item-4 domain corroboration (contract.yaml db_io.schema=omninode_internal,
  2026-08-02 operator ruling, OMN-15656 grants-derivation correction).

Full impacted suite (scripts/ci/tests, scripts/tests, tests/ci, tests/scripts,
tests/unit/scripts) re-run green: 3011 passed, 5 skipped.
…dev rebase

The OMN-15732 deadlock-fix rebase auto-merged two intermediate commits'
TSV additions for node_canary_score_reducer/0003 and
node_projection_registration/0004 with stale checksums, alongside dev's
already-correct rows for the same files (dev holds the adjudicated
single-file 0003 since 211e81e). Take dev's TSV wholesale -- this PR
has no legitimate TSV diff of its own.
@jonahgabriel
jonahgabriel force-pushed the jonah/omn-15737-wire-dep-provenance-gate-external-context branch from b87a344 to 6d52d35 Compare August 8, 2026 18:56
@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

✅ Hostile Reviewer — PASSED

Blocking findings (critical): 0
Total findings: 0
Models succeeded: qwen3-review,qwen3-review-b


Gate semantics (pilot phase)

Verdict Meaning Blocks merge?
passed No critical findings No
blocked CRITICAL findings found Yes
degraded All models unavailable (infra) No (pilot)

Powered by omniintelligence.review_pairing.cli_review — node-based adversarial review via HandlerLlmCliSubprocess (OMN-8468/OMN-8524)

jonahgabriel and others added 3 commits August 16, 2026 07:21
…Dep Provenance Gate + Integration Test Removal Gate EXPECTED_EXTERNAL_CONTEXTS entries; backfill fixture rows
@jonahgabriel
jonahgabriel enabled auto-merge (squash) August 20, 2026 01:43
@jonahgabriel
jonahgabriel merged commit ec8208e into dev Aug 21, 2026
142 of 147 checks passed
@jonahgabriel
jonahgabriel deleted the jonah/omn-15737-wire-dep-provenance-gate-external-context branch August 21, 2026 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant